Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Avri Schneider
    Potential PGP signature verification problem?
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Potential PGP signature verification problem?



    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Hello,

    I have come across a possible problem in the way PGP handles
    signature verification.
    The problem lies in the fact that PGP will strip OLE objects inserted
    in an e-mail and verify the message signature based only on the text,
    not informing the user that objects were striped.
    A WordPad document can be inserted in the e-mail as an OLE object,
    having the same font style and size as the original message.
    An attacker would take a signed message and insert such word document
    anywhere in the message as an OLE object and when the recepient
    checks the signature - the wordpad document is stripped and the
    signature would be valid - The attack would only work if the
    recepient does not use the pgp verified message "text viewer" dialog
    box to read the message but uses it only to verify the validity of
    the signature.

    This was tested with pgp.com's PGP version 8.0, other versions may be
    vulnerable as well.

    I have experimented with older versions and they only worked in the
    hash field of the PGP header which is stripped before the message is
    verified and the same attack can be performed but text would only be
    added at the beginning of the message.

    Regards,
    Avri Schneider
    http://pgp.mit.edu 0x44F87D04

    -----BEGIN PGP SIGNATURE-----
    Version: PGP 8.0 - not licensed for commercial use: www.pgp.com

    iQA/AwUBPm0AKGelhJFE+H0EEQIyxACg7HTH5UjaSGy5D3cobYx0h6 io1lsAnRk1
    cWnPtLBNw3G3XBkZuuUXPgIg
    =fWay
    -----END PGP SIGNATURE-----

  2. #2
    Florian Weimer
    Potential PGP signature verification problem?
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Potential PGP signature verification problem?

    Peter Hanecak <hanecak@megaloman.com> writes:

    > sounds to me like MUA problem, not PGP problem.


    Last tiem I checked, PGP tried to implement MUA support without any
    actual support from the MUA. So it's probably a PGP problem. (Of
    course it's questionable to hack security-critical features into other
    programs in ways like this -- we've seen countless instances of
    surprising features of such combinations.)

    BTW: Maybe Symantec can reconsider the "Strip Cc" BUGTRAQ policy. It
    is a bit annoying when you post follow-ups, and I don't see the point
    in restricting (reasonable) cross-posting.

    --
    Florian Weimer Weimer@CERT.Uni-Stuttgart.DE
    University of Stuttgart http://CERT.Uni-Stuttgart.DE/people/fw/
    RUS-CERT fax +49-711-685-5898

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics